Discover and read the best of Twitter Threads about #fin11

Most recents (1)

A quick thread on observer bias…
In 2011, I was fortunate to be a part of @Mandiant, when the threat intelligence team was just beginning to coalesce. Back then, threat activity came in 3 flavors: APT, FIN, and everything else, and it was a problem...
I created the UNC concept specifically to thwart a form of Observer Bias I had witnessed both inside and outside the IC. If newly observed activity wasn’t quickly attributed to a known threat group it wasn’t deemed important
This, in turn, caused analysts to “try” to fit observed activity into existing groups or have their (often painstaking) reporting lost in the noise, or worse, have their budgets trimmed. This bias caused several attribution cross-pollinations that took years to untangle
Read 7 tweets

Related hashtags

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!